Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

UK Visa Portal Data Breach Exposes Passport and Selfie Data, Raises Urgent Privacy Concerns

Thousands of applicants seeking UK visas have had their passport documents and selfies exposed due to a significant data breach impacting the UK Visa Portal. Despite being notified by researchers, the vulnerability leading to this exposure remained unpatched, and the operating entity, VFS Global, has reportedly engaged legal counsel rather than promptly addressing the security lapse. This incident highlights critical failures in data protection practices by government contractors handling sensitive personal information.

Today's question

Certification mechanisms under Article 42 may serve as an appropriate safeguard for transfers when:

  1. The controller self-certifies compliance, under the international data flow requirements, with particular attention to documentation requirements, consistent with the proportionality principle
  2. Any certification is obtained from any body, in accordance with applicable adequacy requirements, particularly for cross-border operations
  3. The European Commission issues the certificate directly, following the established cross-border transfer framework
  4. The certification is approved under Article 42 and combined with binding and enforceable commitments by the third-country controller/processor under Article 46(2)(f)

Answer this question on the site

Worth knowing

  1. FBI Warns of In Person Data Theft by Extortion Gangs Targeting Law Firms

    The FBI has issued a warning regarding extortion groups physically entering law offices posing as IT support to steal data via USB drives. This novel approach to data theft bypasses traditional cyber defenses and directly targets sensitive client information. The direct physical access by threat actors presents a significant new challenge for data security and privacy.

  2. Shadow AI Use by Employees Concerns Employers about Data Security and Compliance

    A new report reveals that many bosses are overly confident about their knowledge of employees' 'shadow AI' use, despite significant risks. The unauthorized use of AI tools in the workplace can lead to data leakage, intellectual property compromise, and non compliance with data protection regulations. Organizations need better oversight and clear policies to manage the privacy and security implications of AI usage by staff.

  3. 7-Eleven Data Breach Exposes Personal Information of Over 185,000 Individuals

    7-Eleven has confirmed a data breach affecting over 185,000 individuals, exposing their personal information. This incident follows an extortion threat, indicating a potential ransomware or data exfiltration attack. Businesses must prioritize robust cybersecurity measures to protect customer data against increasingly sophisticated cyber threats.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.